CVE-2022-22450: Malicious File Upload
IBM Security Verify Identity Manager 10.0 could allow a privileged user to upload a malicious file by bypassing extension security in an HTTP request. IBM X-Force ID: 224916.
Other sources
IBM Security Verify Identity Manager could allow a privileged user to upload a malicious file by bypassing extension security in an HTTP request.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-22450.
What is the severity of CVE-2022-22450?
The severity of CVE-2022-22450 is low with a CVSS score of 3.8.
How can a privileged user exploit CVE-2022-22450?
A privileged user can exploit CVE-2022-22450 by bypassing extension security in an HTTP request to upload a malicious file.
Which IBM product is affected by CVE-2022-22450?
IBM Security Verify Identity Manager 10.0 is affected by CVE-2022-22450.
Is Linux Linux kernel vulnerable to CVE-2022-22450?
No, Linux Linux kernel is not vulnerable to CVE-2022-22450.
How can I fix CVE-2022-22450?
To fix CVE-2022-22450, IBM recommends applying the necessary patches and updates provided in the official IBM Security Verify Identity Manager documentation.